> Markdown version of [/jobs/ext/1003850-director-cybersecurity-compliance-governance](https://www.wearedevelopers.com/jobs/ext/1003850-director-cybersecurity-compliance-governance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Cybersecurity Compliance & Governance - **Company:** Qarbon Aerospace Inc - **Location:** Red Oak, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Information Systems, PCI Data Security Standards, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Google Cloud, IT General Controls (ITGC), Cyber Threat Analysis, Information Technology, CIS Benchmarks, Cloud Optimization, Devsecops - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=91e9d961a1641c00 ## About the Role Do you have experience in Team leadership?, Do you have a Master's degree?, * Bachelor's degree in Computer Science, Information Security, Information Systems, or a related field; or equivalent experience, * Experience in a publicly traded, regulated, or multi-state enterprise environment * Familiarity with OT/ICS security, cloud security (AWS, Azure, GCP), or DevSecOps practices * Prior experience with CMMC, FedRAMP, or SOX IT general controls ## Description The Director of Cybersecurity, Compliance & Governance is a senior leadership role responsible for establishing and maturing the organization's information security posture, regulatory compliance program, and governance frameworks. Reporting directly to the CIO with a dotted-line relationship to the General Counsel, this role serves as the enterprise authority on cybersecurity strategy, risk management, and compliance obligations across all business units. This leader will partner closely with executive, legal, and operational stakeholders to build a culture of security and compliance, protect critical assets, and ensure the organization meets its obligations under applicable laws, regulations, and industry standards. Principal Accountabilities Cybersecurity Strategy & Operations * Develop, own, and execute the enterprise cybersecurity roadmap aligned with business objectives and risk appetite * Oversee security operations, threat intelligence, incident response, and vulnerability management programs * Lead evaluation and deployment of security technologies including SIEM, EDR, CASB, PAM, and Zero Trust architecture * Manage third-party and vendor risk assessments; enforce contractual security requirements * Direct the organization's Security Operations Center (SOC) function, whether internal or managed Governance, Risk & Compliance (GRC) * Design and maintain the enterprise GRC framework, policies, standards, and control library * Lead compliance programs for applicable regulations (e.g., NIST CSF, ISO 27001, SOC 2, HIPAA, CMMC, PCI-DSS, CCPA/CPRA, TX HB 3746) as applicable * Coordinate internal and external audits; manage findings remediation and management reporting * Maintain a comprehensive risk register; develop risk treatment plans and report risk posture to CIO and Board-level audiences * Partner with Legal on data privacy obligations, contract review, and litigation holds involving electronic evidence Leadership & Program Management * Build, mentor, and retain a high-performing cybersecurity and compliance team * Define team structure, hiring plans, and skill development roadmaps * Manage departmental budget, vendor contracts, and technology investments * Champion security awareness and training programs across the enterprise * Serve as executive-level point of contact for cybersecurity inquiries from clients, partners, regulators, and board members Legal & Cross-Functional Collaboration * Serve as primary liaison to Legal for data breach notification obligations, regulatory inquiries, and e-discovery requests * Advise on cybersecurity implications of M&A activity, new product launches, and third-party partnerships * Collaborate with IT, HR, Finance, and Operations to embed security controls in business processes * Represent cybersecurity interests in enterprise architecture, cloud strategy, and digital transformation initiatives, * 10+ years of progressive experience in cybersecurity, with at least 4 years in a leadership or management role * Demonstrated expertise in GRC frameworks (NIST CSF/800-53, ISO 27001/27002, CIS Controls) * Hands-on experience leading compliance initiatives and managing regulatory audits * Strong understanding of data privacy laws including CCPA, GDPR, and applicable state/federal requirements * Proven ability to communicate risk and security concepts to non-technical executives, legal counsel, and board members * Experience managing security incident response, including coordination with legal, PR, and executive leadership ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)